← Back to CVE List
CVE-2026-87830NVD
Vulnerability Summary
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
CVSS v3.1 Base Metrics — Score 9.1 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone
Affected & Patched Versions
- Apache Wss4j < 2.4.4
- Apache Wss4j >= 3.0.0 and < 3.0.6
- Apache Wss4j >= 4.0.0 and < 4.0.2
- Apache Wss4j 2.4.4
- Apache Wss4j 3.0.6
- Apache Wss4j 4.0.2